300 lines
10 KiB
YAML
300 lines
10 KiB
YAML
argo-cd:
|
|
global:
|
|
image:
|
|
tag: "v2.13.8"
|
|
additionalLabels:
|
|
bu: infra
|
|
team: devops
|
|
podLabels:
|
|
bu: infra
|
|
team: devops
|
|
nodeSelector:
|
|
dedicated: devops
|
|
tolerations:
|
|
- key: "dedicated"
|
|
operator: "Equal"
|
|
value: "devops"
|
|
effect: "NoSchedule"
|
|
dex:
|
|
enabled: true
|
|
resources:
|
|
limits:
|
|
cpu: 250m
|
|
memory: 512Mi
|
|
requests:
|
|
cpu: 250m
|
|
memory: 512Mi
|
|
metrics:
|
|
enabled: true
|
|
podAnnotations:
|
|
prometheus.io/scrape: true
|
|
prometheus.io/path: /metrics
|
|
prometheus.io/port: 5558
|
|
controller:
|
|
replicas: 4
|
|
enableStatefulSet: true
|
|
podAnnotations:
|
|
prometheus.io/scrape: true
|
|
prometheus.io/path: /metrics
|
|
prometheus.io/port: 8082
|
|
resources:
|
|
limits:
|
|
cpu: "7"
|
|
memory: "12Gi"
|
|
requests:
|
|
cpu: "6"
|
|
memory: "8Gi"
|
|
env:
|
|
- name: ARGOCD_CONTROLLER_REPLICAS
|
|
value: '4'
|
|
- name: ARGOCD_RECONCILIATION_JITTER
|
|
valueFrom:
|
|
configMapKeyRef:
|
|
key: timeout.reconciliation.jitter
|
|
name: argocd-cm
|
|
optional: true
|
|
redis-ha:
|
|
enabled: true
|
|
redis:
|
|
startupProbe:
|
|
initialDelaySeconds: 300
|
|
customConfig: |
|
|
repl-backlog-size 50mb
|
|
dir "/data"
|
|
port 6379
|
|
rename-command FLUSHDB ""
|
|
rename-command FLUSHALL ""
|
|
maxmemory 0
|
|
maxmemory-policy volatile-lru
|
|
min-replicas-max-lag 5
|
|
min-replicas-to-write 1
|
|
rdbchecksum yes
|
|
rdbcompression yes
|
|
repl-diskless-sync yes
|
|
save ""
|
|
requirepass replace-default-auth
|
|
masterauth replace-default-auth
|
|
# 1. Increase the timeout (Default is 60s, which is often too low for large RDBs)
|
|
repl-timeout 300
|
|
|
|
# 2. Expand the replication buffer
|
|
# Syntax: client-output-buffer-limit replica <hard-limit> <soft-limit> <soft-seconds>
|
|
# This example gives it 512mb hard limit
|
|
client-output-buffer-limit replica 2000mb 1000mb 300
|
|
|
|
# 3. Increase the backlog size in memory
|
|
repoServer:
|
|
autoscaling:
|
|
enabled: true
|
|
maxReplicas: 25
|
|
minReplicas: 3
|
|
targetMemoryUtilizationPercentage: 75
|
|
targetCPUUtilizationPercentage: 60
|
|
metrics:
|
|
enabled: true
|
|
serviceMonitor:
|
|
enabled: false
|
|
interval: 60s
|
|
podAnnotations:
|
|
prometheus.io/scrape: true
|
|
prometheus.io/path: /metrics
|
|
prometheus.io/port: 8084
|
|
resources:
|
|
limits:
|
|
cpu: "3"
|
|
memory: 5Gi
|
|
requests:
|
|
cpu: "2"
|
|
memory: 4Gi
|
|
env:
|
|
- name: ARGOCD_HELM_ALLOW_CONCURRENCY
|
|
value: 'true'
|
|
- name: GIT_DEPTH
|
|
value: '1'
|
|
- name: ARGOCD_RECONCILIATION_JITTER
|
|
valueFrom:
|
|
configMapKeyRef:
|
|
key: timeout.reconciliation.jitter
|
|
name: argocd-cm
|
|
optional: true
|
|
server:
|
|
replicas: 3
|
|
autoscaling:
|
|
enabled: true
|
|
minReplicas: 3
|
|
maxReplicas: 25
|
|
targetMemoryUtilizationPercentage: 60
|
|
targetCPUUtilizationPercentage: 60
|
|
extraArgs:
|
|
- --insecure
|
|
ingress:
|
|
annotations.nginx.ingress.kubernetes.io/force-ssl-redirect: false
|
|
annotations.nginx.ingress.kubernetes.io/rewrite-target: /
|
|
annotations.nginx.ingress.kubernetes.io/ssl-redirect: false
|
|
enabled: true
|
|
hostname: "argocd-shared-int.meeshogcp.in"
|
|
ingressClassName: nginx-internal
|
|
podAnnotations:
|
|
prometheus.io/scrape: true
|
|
prometheus.io/path: /metrics
|
|
prometheus.io/port: 8083
|
|
resources:
|
|
limits:
|
|
cpu: "2"
|
|
memory: 4Gi
|
|
requests:
|
|
cpu: "1"
|
|
memory: 2Gi
|
|
env:
|
|
- name: ARGOCD_GRPC_KEEP_ALIVE_MIN
|
|
value: '30s'
|
|
applicationSet:
|
|
replicaCount: 2
|
|
notifications:
|
|
metrics:
|
|
enabled: true
|
|
serviceMonitor:
|
|
enabled: false
|
|
resources:
|
|
limits:
|
|
cpu: 500m
|
|
memory: 1Gi
|
|
requests:
|
|
cpu: 300m
|
|
memory: 512Mi
|
|
configs:
|
|
cm:
|
|
resource.customizations: |
|
|
keda.sh/ScaledObject:
|
|
health.lua: |
|
|
local hs = {}
|
|
local healthy = false
|
|
local degraded = false
|
|
local suspended = false
|
|
|
|
if obj.status ~= nil then
|
|
if obj.status.conditions ~= nil then
|
|
for i, condition in ipairs(obj.status.conditions) do
|
|
if condition.status == "False" and condition.type == "Ready" then
|
|
degraded = true
|
|
hs.message = condition.message
|
|
end
|
|
if condition.status == "True" and condition.type == "Ready" then
|
|
healthy = true
|
|
hs.message = condition.message
|
|
end
|
|
if condition.status == "True" and condition.type == "Paused" then
|
|
suspended = true
|
|
hs.message = condition.message
|
|
end
|
|
end
|
|
end
|
|
end
|
|
|
|
if degraded == true then
|
|
hs.status = "Degraded"
|
|
return hs
|
|
elseif healthy == true then
|
|
hs.status = "Healthy"
|
|
if suspended == true then
|
|
hs.message = "ScaledObject is paused as part of normal operations."
|
|
else
|
|
hs.message = "ScaledObject is active."
|
|
end
|
|
return hs
|
|
end
|
|
|
|
hs.status = "Progressing"
|
|
hs.message = "Creating ScaledObject or waiting for conditions."
|
|
return hs
|
|
url: https://argocd-shared-int.meeshogcp.in
|
|
accounts.readonly: 'apiKey,login'
|
|
timeout.reconciliation: 5m
|
|
timeout.reconciliation.jitter: 60s
|
|
statusbadge.enabled: "true"
|
|
help.chatUrl: "https://meesho.slack.com/archives/C021QNS6JLV"
|
|
help.chatText: "Chat now!"
|
|
dex.config: |
|
|
logger:
|
|
level: error
|
|
format: json
|
|
connectors:
|
|
- type: github
|
|
id: github
|
|
name: GitHub
|
|
loadAllGroups: true
|
|
admin.enabled: "true"
|
|
config:
|
|
clientID: Ov23liJzfjWj4b5h6O7v
|
|
clientSecret: $github-sso-secret:dex.github.clientSecret
|
|
orgs:
|
|
- name: Meesho
|
|
params:
|
|
controller.sharding.algorithm: round-robin
|
|
controller.status.processors: '60'
|
|
controller.operation.processors: '30'
|
|
controller.repo.server.timeout.seconds: '90'
|
|
rbac:
|
|
policy.csv: |
|
|
p, role:admins, *, *, */*, allow
|
|
p, role:intern, *, get, *, allow
|
|
p, role:backend-ro, *, get, */*, allow
|
|
## Policy for BACKEND team
|
|
p, role:backend, applications, create, */*, allow
|
|
p, role:backend, applications, get, */*, allow
|
|
p, role:backend, applications, override, */*, allow
|
|
p, role:backend, applications, sync, */*, allow
|
|
p, role:backend, applications, update, */*, allow
|
|
p, role:backend, applications, delete, */*, deny
|
|
p, role:backend, applications, delete/*/Pod/*/*, */*, allow
|
|
p, role:backend, logs, get, */*, allow
|
|
p, role:backend, exec, create, */*, allow
|
|
p, role:backend, projects, get, *, allow
|
|
p, role:backend, projects, sync, *, allow
|
|
p, role:backend, applications, action/apps/Deployment/restart, */*, allow
|
|
## Policy for data-engineering team
|
|
p, role:data-engineering, applications, create, */*, allow
|
|
p, role:data-engineering, applications, get, */*, allow
|
|
p, role:data-engineering, applications, override, */*, allow
|
|
p, role:data-engineering, applications, sync, */*, allow
|
|
p, role:data-engineering, applications, update, */*, allow
|
|
p, role:data-engineering, applications, delete, */*, deny
|
|
p, role:data-engineering, applications, action/apps/Deployment/restart, */*, allow
|
|
p, role:data-engineering, applications, delete, deng-dpcon/*, allow
|
|
p, role:data-engineering, applications, delete/*/Pod/*/*, deng-*/*, allow
|
|
p, role:data-engineering, logs, get, */*, allow
|
|
p, role:data-engineering, exec, create, */*, allow
|
|
p, role:data-engineering, projects, get, *, allow
|
|
p, role:data-engineering, repositories, update, */*, allow
|
|
## Policy for bharatml team
|
|
p, role:bharatml-role, applications, get, dsci-*/int-predator-*, allow
|
|
p, role:bharatml-role, applications, get, dsci-*/int-model-inference-*, allow
|
|
p, role:bharatml-role, applications, action/apps/Deployment/restart, dsci-*/int-predator-*, allow
|
|
p, role:bharatml-role, applications, action/apps/Deployment/restart, dsci-*/int-model-inference-*, allow
|
|
p, role:bharatml-role, applications, delete/*/Pod/*/*, dsci-*/int-predator-*, allow
|
|
p, role:bharatml-role, applications, delete/*/Pod/*/*, dsci-*/int-model-inference-*, allow
|
|
p, role:bharatml-role, applications, update/keda.sh/ScaledObject/*/*, dsci-*/int-predator-*, allow
|
|
p, role:bharatml-role, applications, update/keda.sh/ScaledObject/*/*, dsci-*/int-model-inference-*, allow
|
|
p, role:bharatml-role, applications, sync, dsci-*/int-predator-*, allow
|
|
p, role:bharatml-role, applications, sync, dsci-*/int-model-inference-*, allow
|
|
p, role:bharatml-role, applications, sync, dsci-*/int-horizon*, allow
|
|
|
|
## Policy for Admin-NoDelete role
|
|
p, role:admin-nodelete, *, get, *, allow
|
|
p, role:admin-nodelete, *, create, *, allow
|
|
p, role:admin-nodelete, *, update, *, allow
|
|
p, role:admin-nodelete, applications, override, *, allow
|
|
p, role:admin-nodelete, applications, sync, *, allow
|
|
p, role:admin-nodelete, applications, action/*, *, allow
|
|
p, role:admin-nodelete, applications, delete/*/Pod/*/*, */*, allow
|
|
g, Meesho:devops-new, role:admin-nodelete
|
|
## Teams and policy mapping
|
|
g, Meesho:devops, role:admin
|
|
g, Meesho:backend, role:backend
|
|
g, Meesho:live-commerce, role:live-commerce
|
|
g, Meesho:devops-interns, role:intern
|
|
g, ringmaster, role:backend
|
|
g, bharatml, role:bharatml-role
|
|
g, Meesho:data-engineering, role:data-engineering
|
|
g, readonly, role:backend-ro
|